Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: iXsecurity.20020404.4d_webserver.a

iXsecurity.20020404.4d_webserver.a

From: Jonas Ländin <Jonas.Landin_at_ixsecurity.com>
Date: Fri, 3 May 2002 02:37:45 +0200

iXsecurity Security Vulnerability Report
No: iXsecurity.20020404.4d_webserver.a
==================================

Vulnerability Summary
---------------------
Problem: The 4D webserver has a buffer overflow
condition.

Threat: An attacker could make the webserver crash
and
                                       possibly execute arbitrary code.

Affected Software: 4D Webserver version 6.7.3 verified.

Platform: Windows verified.

Solution: Update to the version mentioned below.

Vulnerability Description
-------------------------
An attacker could overflow the username or password field in a basic
authentication resulting in EIP overwrite and possible arbitrary code
execution. There are a few checks of the buffer, including a check to make
sure only "valid" characters are sent. If "invalid" characters are found
the copy is terminated. Ironicaly there is no bounds check. Because of the
various checks, it is a bit more complicated to exploit, since it minimizes
the code one can include in the buffer.

Solution
-------
The solution for Bug Number: ACI0021102 is to upgrade to the latest
version, which will be 4D 6.7.4 or 4D 6.8.1.

Additional Information
----------------------
4D was contacted 20020405.

This vulnerability was found and researched by
Patrik Karlsson & Jonas Ländin
patrik_at_cqure.net
jonas_at_cqure.net

This document is also available at: http://www.cqure.net/advisories/
Received on May 03 2002

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos